GHSA-qqhf-xfhw-7884

Suggest an improvement
Source
https://github.com/advisories/GHSA-qqhf-xfhw-7884
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-qqhf-xfhw-7884/GHSA-qqhf-xfhw-7884.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qqhf-xfhw-7884
Aliases
Published
2022-11-04T12:00:25Z
Modified
2023-11-08T04:10:31Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Markdownify has Files or Directories Accessible to External Parties
Details

Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough) and/or does not properly validate the contents of markdown files before rendering them.

Database specific
{
    "cwe_ids":  [
        "CWE-552"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-11-04T20:49:16Z",
    "nvd_published_at":  "2022-11-03T20:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / electron-markdownify

Package

Name
electron-markdownify
View open source insights on deps.dev
Purl
pkg:npm/electron-markdownify

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-qqhf-xfhw-7884/GHSA-qqhf-xfhw-7884.json"